Recitare is built privacy-first: encrypted storage, automatic PII redaction, no AI training on your content, and delete-anytime control.
Six layers of protection built into every interaction.
Max automatically scans for sensitive data (Social Security and National Insurance numbers, phone numbers in US, UK and international formats, email addresses, credit cards, IBANs, street addresses and postcodes) and replaces it with [PROTECTED] placeholders before your text is sent for AI analysis: questions, summaries, and study guides. For documents about other people, optional Name Protection hides personal names too. (Text sent for speech synthesis is spoken exactly as written, so it is protected by our providers' no-training terms rather than redaction.)
Your documents are not used to train Google Gemini, Anthropic Claude, or any other AI model — their API terms prohibit training on submitted data. For repeat questions on the same document, text may be briefly cached by the AI provider (up to ~30 minutes) to speed up responses, then discarded.
All data transmitted between your browser and our servers uses TLS 1.2+ encryption. Documents stored in our database are encrypted at rest. Your content travels through secure channels at every step.
You can review a complete history of every AI action on your documents — what ran, when, and with which model — anytime from your account. Built so YOU can verify what Max did, not so we can watch you.
Delete any document, summary, or your entire account at any time. Deleted items enter a 30-day recovery window, then are permanently erased — documents, cached audio, and AI outputs alike. Your subscription, your data, your rules.
Max cites specific page numbers when generating summaries and study guides. Every claim links back to your source document, so you can verify Max’s work — not just trust it.
Pattern matching can recognise a phone number. It cannot recognise a name. For transcripts and other documents about real people, tick Protect names in this document when you upload, or switch it on later from the More menu in the reader.
A small language model runs inside your browser and picks out the personal names. Your document is not sent anywhere for this step. The model is downloaded once from Hugging Face, then kept in your browser.
Before a question, summary, study guide or library search goes to our AI providers, each name is swapped for a neutral token such as [PERSON_3fa9c1b20d4e].
The swap happens on our server, at the single point where text leaves for an AI provider, and the names are put back before the answer reaches you. The list of names is stored with your document, which already contains them, and is deleted with it.
Every AI provider we work with is held to strict data handling standards.
Google Gemini
Document analysis, summaries, study guides, chat
1M token context; not used to train models
Inworld
Text-to-speech for all listening tiers
Real-time synthesis, not used for model training
Anthropic Claude
Image and diagram analysis (OCR)
Not used to train models
Clear promises, no fine print.
We never sell your data — period.
AI providers do not train on your content by default.
Automatic PII redaction runs before AI analysis, and optional Name Protection hides personal names too.
You can export or delete your data at any time.
Common questions about privacy, security, and how Max handles your data.
We’re happy to walk you through our architecture and data handling practices.